Manage an environment in Azure
An environment represents the infrastructure that is used for application delivery. The necessary infrastructure, such as gateways, agents, and NetScalers, is prepared as part of the environment deployment. Once deployed, this environment can be used to deliver multiple applications.
Prerequisites
The service creates three subnets in Azure for deploying the app delivery infrastructure. Each subnet has 255 addresses. That is, the service blocks 765 (3*255) IP addresses.
-
Ensure that the VNet CIDR block size where the app delivery infrastructure is deployed has enough space to accommodate three subnets of 255 addresses.
-
To deploy the environment in one or more availability zones, the VNet CIDR block size must be greater than the /22 netmask (1,024 IP addresses). Since the infrastructure is deployed in one availability zone, we recommend not to use it for a production environment. It is best suited for staging or POC.
-
A virtual machine in the VNet must have access to the Internet through the external Azure load balancer (ALB) created by the service and must be able to resolve the DNS. The agent communicates with the service at
<pop>.appdeliverysecurity.cloud.comthrough the external ALB and it must be able to resolve the domain.
Specify a subnet
-
Navigate to NetScaler® Managed > App Environments > Environment tab.
-
Click Create and select Azure.
-
Select Specify NetScaler subnet to reach the origin application servers.
-
Select the subnet.
Note:
If your origin application servers are outside the current Azure account, ensure that the server subnet that you have added are configured to route the traffic to the origin application server subnets.
Connect to an origin application server outside the Azure account
The service allows you to add the origin application servers that are deployed outside the current Azure account. For example, consider that the origin application server is in a VNet belonging to another Azure account, a private data center, or in another cloud account.
Prerequisites
-
The origin application server VNet cannot have overlapping CIDRs with the app delivery infrastructure VNet.
-
The origin application server VNets must have unique CIDRs.
-
To avoid latency between the app delivery infrastructure VNet and the origin application servers, both must be in the same region.
To add origin application servers outside your Azure account, you must create a specific subnet that the app delivery infrastructure must use to reach the origin application servers. While creating an Azure environment, on the Create Azure Environment page, select Specify NetScaler subnet to reach the origin application servers and add the required subnet. Only if Specify NetScaler subnet to reach the origin application servers is selected, the External tab gets enabled. Add the IP address or subnet of the origin application server. For more information, see Specify a subnet.
For this deployment to work, you must ensure network connectivity between the origin application servers and the app delivery infrastructure. The app delivery infrastructure must be able to send traffic to the origin application servers and also receive traffic from the origin application servers.
Create an environment
-
Naviagte to NetScaler Managed Apps > App Environments.
-
In the Environments tab, click Create and select Azure.
-
In the Create Azure Environment page, specify values for the following parameters:
-
Name
-
Cloud Access Profile
-
Azure Region
-
Azure Resource Groups
-
Azure Virtual Network
-
Availability Zones
-
-
Add a Device Access Profile or select an existing profile. To create a profile, provide a name and a password. You can use these credentials to login to the NetScaler.
-
If you want app delivery infrastructure to be deployed in a specific subnet, select Specify NetScaler subnet to reach the origin application servers and add the subnet value.
-
Select the following tabs based on where your origin application server sites are present:
-
Internal: Select when the origin application servers and app delivery infrastructure are present in the same VNet. Select the Origin application servers present in the same VNet check box.
-
External: Select when the origin application servers are outside the Azure account. You must establish a connection between the app delivery infrastructure and the external subnets where the origin application servers are deployed.Note:The External tab becomes visible only when Specify subnets to be used by the app environment to reach the origin application servers is selected.
-
-
Add any tags for resources if required by your Azure subscription.
-
Click Create.
Undeploy an environment
When you undeploy an environment that has one or more applications in the DEPLOYED state linked to it, all the applications associated with that environment are forcefully deleted upon confirmation. You can choose to first delete the application, and then undeploy the environment.